Security and privacy
This page is how the product behaves. The privacy policy and the terms are the legal notices. Where they cover the same fact, they should match. The policy is the contract.
What we store for the account
- Email address, a password hash (or the email from Google or Apple), session cookie, and email-verification and reset tokens.
- Billing status from Stripe: plan, subscription state, and invoice metadata. Not the full card number.
- The domains you add, origin host, DNS mode, certificate and distribution identifiers, and the firewall rules on each site.
- Encrypted Cloudflare or GoDaddy credentials, if you connect them. They are not shown back in the form.
- Alert preferences, Slack and webhook URLs you save, and the time of the last spike mail and the last digest.
- Change-history rows and the operator audit log, from the version that started recording.
- Authenticator secrets and unused recovery-code hashes, if you turn MFA on.
IP addresses
The WAF has to see a client address to filter a request. The privacy policy says request metadata such as IP address, time, path, method, country, and the rule that matched is processed for that, and that authorization and cookie headers are redacted before logging.
What the product stores for you is narrower. Copilot samples keep a masked address: the last IPv4 octet, or the last IPv6 group, is replaced. A value that is not an IP is dropped. Change history does not store a full IP address. Alert mail masks addresses before they are sent. Allowlist suggestions are built from path and method, not from a client address.
That mask is the app’s copy. It is not a claim that Amazon’s own logs never contain an address. Those logs are part of running the edge.
Origin verify
Advanced settings can send a secret header, X-PMW-Origin-Verify, from the edge to your origin so the origin can reject requests that skip the shield. It is off until you enable it. Enabling it does not install the check on your origin. You copy the secret and do that yourself. Until you do, the header is unused.
Rotate replaces the secret. Disable stops sending it. Reveal shows the secret to someone who can manage the site. The header is optional. Go-live does not require it, and turning it on does not block visitors at the WAF.
Sessions and abuse controls
The dashboard session is one essential cookie. Public forms use a honeypot and a per-IP rate limit in the app. The marketing site’s own edge can also rate-limit. Those controls are for this website. They are not the WAF on a customer origin.